Infosecurity News

Bad Rabbit Ransomware Spreads In Russia, Ukraine
BadRabbit, believed to be a Petya variant, could also be tied to attacks on critical infrastructure in Ukraine.

Third Man Pleads Guilty to 'Celebgate' iCloud Attacks
Scores of celebs fell for simple phishing campaign

Young Adults More Likely to Fall for Phishing Scams
Get Safe Online finds over-55s are more cautious online

DDoS Attack Takes Czech Election Sites Offline
Barrage follows parliamentary elections

APT28 Targets Cybersecurity Experts in Latest Spy Campaign
The payload allows screenshot capture, data and configuration exfiltration, remote code execution and file downloading.

Fake Cryptocurrency Trading Apps Harvest Credentials and Steal Cash
The apps steal Poloniex login credentials, and trick victims into making their Gmail accounts accessible.

US Government Warns CNI Firms of Dragonfly Attacks
New campaign focused on stealing ICS and SCADA data

Reaper Botnet Has Come for the Internet
Reaper is much bigger and more sophisticated than Mirai—and it's still just a baby.

US Consumers Willing to Trade eCommerce Convenience for Security
Survey contradicts the widely-held belief that consumers value convenience and experience over security.

FBI Seeks DDoS Attack Evidence from Victims
The FBI has requested that US victims of DDoS attacks share the details of the experience

25% of Mail Claiming to Be from Federal Agencies is Fraudulent
As mandate comes down, 82% of federal domains lack DMARC for email security, and have 90 days to implement it.

Domino’s Australia Blames Former Supplier for Info Leak
Customers complain of personalised spam from company

UK Cybercrime Falls but Stats Are Still Shaky
ONS figures show 1.6 million incidents of computer misuse

GCHQ Collects Mass Social Media Data on Millions in UK—Report
The spy agency allegedly has collected info for decades, sharing it with foreign intelligence and law enforcement.

Employee Snooping is Widespread, with Most Looking for Sensitive Info They Don't Need
Nearly two in three IT security pros admit they've specifically sought out company information they didn’t need.

Third of IoD Members Have Never Heard of GDPR
Institute calls on government and regulator to step up outreach efforts

ROCA Crypto Bug Compromises RSA Keys
Organizations urged to hunt down vulnerable Infineon chips

Report: 88% of Java Apps Vulnerable to Attacks from Known Security Defects
New Veracode report exposes the risks companies face from vulnerable open source components

Google Rolls Out Advanced Protection for High-Risk Users
Users include journalists who need to protect the confidentiality of their sources, or people in abusive relationships.

DHS Mandates DMARC, HTTPS for All US Federal Agencies
Agencies will have 90 days to implement DMARC and 120 days to upgrade to HTTPS.



